Concepts & common attacks
Well-implemented cryptography is rarely “broken” by brute-forcing the algorithm: it’s broken by how it’s used. This card is the map of the area: the concepts you must be clear on and the catalog of implementation flaws that show up again and again in audits, CTFs, and bug bounty. The other Cryptography cards go deep on each block.
The four services
Section titled “The four services”Confidentiality only the recipient reads the message -> encryption (sym/asym)Integrity the message wasn't altered -> hash, MACAuthenticity the message comes from who it claims -> MAC, digital signatureNon-repudiation the sender can't deny sending it -> digital signature (asymmetric)Confusing these services is the root of many flaws: encryption does not give integrity (that’s why authenticated encryption, AEAD, exists), and a hash does not give authenticity (that’s why HMAC exists, not “hash(key‖message)”).
Primitives and what each is for
Section titled “Primitives and what each is for”Symmetric encryption AES, ChaCha20 lots of data, shared key (see crypto-sym)Asymmetric encryption RSA, ECC key exchange / signing (see crypto-pki)Hash SHA-256, SHA-3 integrity fingerprint (see crypto-hash)MAC / AEAD HMAC, AES-GCM integrity + authenticityKDF PBKDF2, scrypt, Argon2 derive key from password (slow on purpose)Digital signature RSA-PSS, Ed25519 authenticity + non-repudiationImplementation-flaw catalog (what actually gets exploited)
Section titled “Implementation-flaw catalog (what actually gets exploited)”Kerckhoffs: security is in the KEY, not the secrecy of the algorithm-> "custom crypto" / rolling your own = almost always broken
ECB mode equal blocks -> equal ciphertext (the "ECB penguin"); pattern leakReused IV/nonce catastrophic in CTR/GCM (see crypto-sym); a GCM nonce must NEVER repeatPadding oracle the padding error distinguishes -> decrypt without the key (crypto-padding)Missing/bad MAC encrypt without authenticating -> bit-flipping, malleability (use AEAD)Hash for passwords "bare" SHA-256 is crackable; use Argon2/bcrypt (see crypto-hash)Weak RNG predictable keys/tokens (see crypto-rng)Non-constant compare == on MACs/tokens -> timing attack; use constant-time comparisonLength extension SHA-256(secret‖msg) is extensible -> use HMAC (see crypto-hash)Downgrade / curves accepting weak algorithms (RC4, MD5, export) -> force the weakestAttack approach (CTF / audit)
Section titled “Attack approach (CTF / audit)”1. Identify the primitive and mode (block length, output format, headers)2. Which service is MISSING? (is there a MAC? is the IV random? is padding validated?)3. Find the oracle: does the system reveal anything (error, timing, length) on manipulated input?4. Exploit the property, not the algebra: malleability, reuse, error oracles- CyberChef (interactive analysis/transform), Python + PyCryptodome (prototyping attacks).
- hashcat / John (cracking, see Hashing & cracking), sage/z3 for the math in challenges.
- openssl to inspect real ciphers, certificates, and protocols.
Defense
Section titled “Defense”- Don’t implement your own primitives: use vetted libraries (libsodium, Tink) and AEAD by default (AES-GCM, ChaCha20-Poly1305).
- Derive password keys with Argon2id; generate keys/nonces with a CSPRNG.
- Compare secrets in constant time; verify the MAC before decrypting (encrypt-then-MAC).
- Crypto inventory and agility to rotate algorithms (post-quantum readiness).
CVEs and real-world cases
Section titled “CVEs and real-world cases”- ROBOT (2017): RSA PKCS#1 v1.5 padding oracle revived at Facebook, PayPal, etc.
- Heartbleed (CVE-2014-0160) and POODLE (CVE-2014-3566): implementation/design flaws with massive impact (see TLS).
- DROWN, Logjam, FREAK: downgrade to weak “export” crypto.
- Countless CTFs and real bugs from static IVs, ECB in session cookies, and unsalted hashes.
Testing checklist
Section titled “Testing checklist”- Identify primitive, mode, and ciphertext format
- Missing integrity/authenticity? (no MAC → malleability)
- ECB? → look for pattern leakage with repeated blocks
- Reused or predictable IV/nonce?
- Probe oracles (padding, error, timing)
- Passwords: slow+salted hash or crackable?
- Tokens/keys: CSPRNG or predictable? (see Weak randomness (RNG))
- Are weak algorithms accepted (downgrade)?